CVE-2016-7040
published 2016-10-07CVE-2016-7040: Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI…
PriorityP354high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.26%
81.0th percentile
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms_management_engine | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7fr4-2q4f-xgw5: Red Hat CloudForms Management Engine 4
ghsa_unreviewed·2022-05-17
CVE-2016-7040 [HIGH] CWE-284 GHSA-7fr4-2q4f-xgw5: Red Hat CloudForms Management Engine 4
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.
Red Hat
cfme: Incorrect sanitization in regular expression engine
vendor_redhat·2016-10-04·CVSS 8.8
CVE-2016-7040 [HIGH] CWE-20 cfme: Incorrect sanitization in regular expression engine
cfme: Incorrect sanitization in regular expression engine
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.
An input validation flaw was found in the way CloudForms regular expressions were passed to the expression engine via both the JSON API and the web based UI. A user with the ability to view collections and filter them could use this flaw to execute arbitrary shell commands on the host with the privileges of the CloudForms process.
Package: cfme (CloudForms Management Engine 5.2) - Affected
Package: cfme (CloudForms Management Engine 5.3) - Aff
No detection rules found.
No public exploits indexed.
2016-10-07
Published